Qcs4490 Firmware
by Qualcomm
CVEs (259)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28574 | Cri | 0.59 | 9.0 | 0.00 | Nov 7, 2023 | Memory corruption in core services when Diag handler receives a command to configure event listeners. | ||
| CVE-2023-28540 | Cri | 0.59 | 9.1 | 0.00 | Oct 3, 2023 | Cryptographic issue in Data Modem due to improper authentication during TLS handshake. | ||
| CVE-2025-47392 | Hig | 0.57 | 8.8 | 0.00 | Apr 6, 2026 | Memory corruption when decoding corrupted satellite data files with invalid signature offsets. | ||
| CVE-2023-21673 | Hig | 0.57 | 8.7 | 0.00 | Oct 3, 2023 | Improper Access to the VM resource manager can lead to Memory Corruption. | ||
| CVE-2024-21464 | Hig | 0.55 | 8.4 | 0.00 | Jan 6, 2025 | Memory corruption while processing IPA statistics, when there are no active clients registered. | ||
| CVE-2024-33056 | Hig | 0.55 | 8.4 | 0.00 | Dec 2, 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. | ||
| CVE-2024-33060 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2024 | Memory corruption when two threads try to map and unmap a single node simultaneously. | ||
| CVE-2024-33045 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2024 | Memory corruption when BTFM client sends new messages over Slimbus to ADSP. | ||
| CVE-2024-33035 | Hig | 0.55 | 8.4 | 0.00 | Sep 2, 2024 | Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients. | ||
| CVE-2024-33034 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time. | ||
| CVE-2024-33023 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events. | ||
| CVE-2024-23384 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker. | ||
| CVE-2024-23382 | Hig | 0.55 | 8.4 | 0.00 | Aug 5, 2024 | Memory corruption while processing graphics kernel driver request to create DMA fence. | ||
| CVE-2024-23380 | Hig | 0.55 | 8.4 | 0.00 | Jul 1, 2024 | Memory corruption while handling user packets during VBO bind operation. | ||
| CVE-2024-23373 | Hig | 0.55 | 8.4 | 0.00 | Jul 1, 2024 | Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released. | ||
| CVE-2024-23372 | Hig | 0.55 | 8.4 | 0.00 | Jul 1, 2024 | Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size. | ||
| CVE-2024-21461 | Hig | 0.55 | 8.4 | 0.00 | Jul 1, 2024 | Memory corruption while performing finish HMAC operation when context is freed by keymaster. | ||
| CVE-2024-23354 | Hig | 0.55 | 8.4 | 0.00 | May 6, 2024 | Memory corruption when the IOCTL call is interrupted by a signal. | ||
| CVE-2024-23351 | Hig | 0.55 | 8.4 | 0.00 | May 6, 2024 | Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions. | ||
| CVE-2024-21471 | Hig | 0.55 | 8.4 | 0.00 | May 6, 2024 | Memory corruption when IOMMU unmap of a GPU buffer fails in Linux. |
- risk 0.59cvss 9.0epss 0.00
Memory corruption in core services when Diag handler receives a command to configure event listeners.
- risk 0.59cvss 9.1epss 0.00
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
- risk 0.57cvss 8.8epss 0.00
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
- risk 0.57cvss 8.7epss 0.00
Improper Access to the VM resource manager can lead to Memory Corruption.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while processing IPA statistics, when there are no active clients registered.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when two threads try to map and unmap a single node simultaneously.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.
- risk 0.55cvss 8.4epss 0.00
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while processing graphics kernel driver request to create DMA fence.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while handling user packets during VBO bind operation.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size.
- risk 0.55cvss 8.4epss 0.00
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when the IOCTL call is interrupted by a signal.
- risk 0.55cvss 8.4epss 0.00
Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.
- risk 0.55cvss 8.4epss 0.00
Memory corruption when IOMMU unmap of a GPU buffer fails in Linux.
Page 2 of 13